RE: Increase seen in port probes since Tuesday afternoon

From: James C Slora Jr (Jim.Slora_at_phra.com)
Date: 12/30/04

  • Next message: Martin Mačok: "Re: Increase seen in port probes since Tuesday afternoon"
    To: "'BahdKo'" <bahdko@erols.com>, <incidents@securityfocus.com>
    Date: Thu, 30 Dec 2004 14:44:51 -0500
    
    

    BahdKo wrote Thursday, December 30, 2004 04:23

    > Since Tuesday afternoon EST I've seen a dramatic increase in
    > the number of machines probing my network on ports 2745,
    > 1025, 3127, 6129, and usually 80. Each probe involves the
    > machine sending three packets to each port.

    Yes from time to time. The port pattern is typical of many botnets, many of
    which will focus multiple drones against a particular IP space for a while.

    Packet captures might reveal whether there is anything new or interesting
    about any of the individual probes. The three packets would probably be
    standard Syn retries. Again a packet capture would show whether or not this
    is the case. If a destination device is listening on any of those ports, a
    packet capture might also give an indication about whether there is some new
    payload.


  • Next message: Martin Mačok: "Re: Increase seen in port probes since Tuesday afternoon"

    Relevant Pages

    • Re: I am sick of windows firewall
      ... I use the AnalogX IPsec rules to supplement BlackIce ... need IPsec to stop outbound that BlackIce cannot do by ... attempts on the Windows networking ports even though BI ... supplemental packet filtering solution. ...
      (comp.security.firewalls)
    • Re: N00b Question
      ... There is a great product called packet shaper by packetteer. ... AIM, iTunes, etc... ... ports and IP's this device will detect it. ... > For MSN/yahoo chat you can block the ports in your external firewall. ...
      (Security-Basics)
    • Re: WSAAsyncSelect stopped working
      ... the utility sends out a UDP back and waits for an ACK using ... is blocking any ports. ... the receipt of a packet, ... Netstat -a shows the UDP port on the PC side open. ...
      (microsoft.public.win32.programmer.networks)
    • Re: Stateful Packet Inspection Firewall
      ... and inspects packet contents for legality. ... > ports but also controls which applications can access the net / listen ... Presumably SPI does not place any restrictions on client ... explicit or implicit rule within the rulebase, ...
      (comp.security.firewalls)
    • Re: Speed Mismatch?!?
      ... Try a test with an iperf buffer of less than 1 packet. ... local performance by setting the TCP Receive Window to ... the buffers between Gi ports and Fa ports are not working ... then adding a "buffering" switch to the path would help. ...
      (comp.dcom.sys.cisco)